Embedded app vault
The app uses its own exact origin and host-scoped RP ID. Its encrypted records live in a separate tenant namespace.
- Independent credentials per app
- Copied, reviewed browser modules
- Ranger pilot is the reference
Developer platform
Use the hosted encrypted-vault API today. Keep application tenants isolated, require passkeys, and keep plaintext keys out of requests and logs.
// Your application
generateOrImportKey()
→ encryptInBrowser()
→ saveCiphertext()
// The service stores
{
envelope,
credential,
revision
}
// The service never receives
decryptedKey | passkeyOutput
Choose the boundary
Passkeys are bound to a domain. Choose the model that matches where the wallet should live.
The app uses its own exact origin and host-scoped RP ID. Its encrypted records live in a separate tenant namespace.
The Ranger pilot opens a popup at this origin and keeps keys and transaction approval outside the app page. Each future subDAO needs an explicit origin registration and transaction policy.
Everything you need
Origin registration, browser requirements, rollout and test plan.
Read guide ↗ 02Challenges, sessions, encrypted revisions and errors.
Read API ↗ 03Machine-readable routes, schemas and authentication rules.
Open schema ↗ 04Recovery, trust boundaries and current limitations.
Review model ↗